Internal AI tools touch real company data, real permissions, and sometimes real actions. Here is how to build one that is actually secure without adding unnecessary complexity.
How I built a custom code execution engine backed by a Rust/Axum microservice, embedded directly in blog articles. Covers the security model, subprocess isolation with setrlimit, HMAC request signing, and the tradeoffs behind every decision.